EP Waivers
EP Waivers adds versioned liability waivers and health declarations to a studio. A signature records the typed name, the timestamp, the IP address, the user agent and the exact version of the document that was agreed to, and it is kept as an immutable legal record. Publishing a new version requires everyone to re-sign before their next class.
Published by ElmsPark Studio.
Overview
Section titled “Overview”- Versioned documents. Publishing a new version does not rewrite history: the earlier signature is retained as the record of what that member actually agreed to at the time.
- Immutable e-signatures. Typed name, timestamp, IP, user agent and version, stored as a legal record.
- Health declarations. Encrypted at rest and shown only to admins and, through EP Instructors, the teacher assigned to the class.
- Hard gate at booking. Through the EP Events booking hook, an unsigned applicable waiver blocks the booking; the buyer signs inline before payment and the booking then continues.
- Re-sign notifications when a new version is published.
- Coverage surfaces. Who has signed, on which version, with a coverage log and read-only API and MCP tools.
- No public surface. The record survives a GDPR erasure of marketing data, because it is a legal record rather than marketing consent.
Requirements
Section titled “Requirements”- PageMotor 0.8.3b or later (PageMotor 0.9, 0.10 and 0.11 all supported)
- EP Events 1.0.28 or later for the booking gate
- EP Instructors if teachers should see health answers for their own classes
Installation
Section titled “Installation”ep-waivers.zipcomes with an EP Suite licence — ElmsPark supplies it directly (see EP Suite plugins); after install it updates through your site’s Updates screen.- Upload via Plugins → Manage Plugins. Activate.
- Create a waiver document, publish its first version, and place
[ep-waiver-sign]on the page where members should sign.[ep-waiver-status]shows a member their current status.
Changelog
Section titled “Changelog”1.2.15
Section titled “1.2.15”- The signed copy sent after a confirmation link now uses EP Email’s sending method. When a member confirmed their signature from the emailed link, their signed copy was sent through your server’s built-in mail instead of the sending method set in EP Email. It now goes out through EP Email, using the sending method you set there (Mailgun, Brevo, SMTP and so on), and shows in EP Email’s delivery log.
1.2.14
Section titled “1.2.14”- Settings language menu. The language menu in this plugin’s settings now lists only the languages it is actually translated into, plus English, so you can no longer pick a language that changes nothing.
1.2.13
Section titled “1.2.13”- A signature now has to come from the person named on it. Until now anyone could type any email address into the waiver form and sign it, and that signature let the named member book. A member who is signed in and signs for their own email is still signed straight away. Anyone else (a visitor who is not signed in, or a signed-in member signing for a different email) now gets an email with a confirmation link, and the signature only counts once that link is used. The link works once and lasts 7 days.
- Everyone who signed before this update stays signed. Their signatures are kept as confirmed, so no existing member has to sign again or is stopped from booking.
- Booking a class through EP Events while not signed in now needs that confirmation. After signing, the booking stops with a message asking the customer to confirm from their email and then book again. Signed-in members booking for themselves are not affected.
- The waiver someone agreed to is the one they read. If you publish a new version while someone has the old one open, their signature is no longer recorded against the new text: they are asked to reload the page and read it first.
- Waiver emails now go through EP Email. The signed copy, the new confirmation email and the re-sign notice used to bypass EP Email and rely on your host’s basic mail function, which many hosts discard. They now use EP Email and your chosen provider, fall back to the host’s mail function only if EP Email is missing or fails, and log a message if an email cannot be sent.
- Re-sign notices for a new version now go only to confirmed signers, and the Coverage figures count only confirmed signatures. Unconfirmed signatures show in the Coverage list marked as awaiting confirmation.
1.2.12
Section titled “1.2.12”- Security: someone who was not signed in could overwrite or erase another member’s health declaration. The signing form accepts a typed email address from visitors who are not signed in, and signing replaced the health and injury notes held for that address. Anyone could therefore wipe a member’s declared injury, which is what the teacher reads before class. Signing without being signed in can now only add a dated note beneath what is already held, marked as added without signing in. It can no longer remove or change it.
- Leaving the health box empty no longer erases what you told the studio before. Re-signing after a new waiver version, with the optional health box left blank, used to wipe your earlier declaration. A blank box now leaves it as it was. Members who are signed in and type something new still replace their own declaration, as before.
1.2.11
Section titled “1.2.11”- Prevents the plugin failing to load on PageMotor 0.11.3. Two of its internal methods, which encrypt health declarations at rest, share their names with methods PageMotor adds in 0.11.3. That stops PHP loading the plugin, and PageMotor’s safe mode would have disabled it.
- Nothing about how your data is stored changes, and existing signatures and health declarations are unaffected.
- Update before you move the site to PageMotor 0.11.3.
1.2.10
Section titled “1.2.10”- Corrects the PageMotor 0.11.3 preparation shipped in 1.2.9. That release grouped this plugin’s API and MCP actions into families, but in a shape PageMotor 0.11.3 does not accept. On 0.11.3 the plugin would have registered none of its actions, and nothing on screen would have said so.
- This version uses the shape 0.11.3 expects, and keeps the earlier shape for sites still on an older PageMotor. One build serves both, so there is no order you have to update things in.
- Safe to install now. Nothing you can see changes.
Defensive load guard: if the bundled suite library is missing or truncated, the plugin now degrades to behaving as though it were not installed, with a note in the error log, instead of taking the whole site down with it. The build also verifies the bundled library is really present inside the shipped zip. No change in behaviour when everything is healthy.
Namespaced shortcodes. PageMotor’s shortcode registry is first-wins and core initialises first, so a bare name can silently lose to a core shortcode of the same name. [ep-waiver-sign] and [ep-waiver-status] are now the canonical forms. The old [waiver-sign] and [waiver-status] still work as deprecated aliases, so existing pages keep working.
The admin check now routes through a version-skew-safe wrapper, so a mismatch between suite plugins can never break this plugin’s admin screens. No functional change.
PageMotor 0.10 compatibility: the admin guard used a check that 0.10 removed, which failed closed and locked admins out of the plugin’s admin actions. Both 0.9 and 0.10 are now supported.
Admin polish and a counting fix. The Signatures column counted every historical version, so a member who re-signed after a version bump was counted twice; it now counts members signed on the current version, while prior signatures stay in the coverage log as the legal record. The version badge now appears in the admin header. Publish and Create no longer submit the whole settings form when clicked early. New-document fields are labelled, and the version textarea is taller for pasting real legal text.
Booking pre-payment gate through the EP Events hook: an unsigned applicable waiver blocks the register, the buyer signs inline, then the booking resumes.
Health declaration capture, encrypted at rest, re-sign notifications on a new version, and the status shortcode.
First release: versioned waiver documents, immutable typed-name e-signatures, the signing shortcode, and the admin documents and coverage surfaces.